suede-mcp-qa — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited suede-mcp-qa (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill when a Suede MCP server or MCP docs surface changes.
initialize, ping, tools/list, tools/call,resources/list, resources/read, prompts/list, and prompts/get when supported.
malformed JSON-RPC messages.
| Failure type | Severity | Action |
|---|---|---|
| Server fails to start | Critical | Stop. Report startup error verbatim. |
tools/list returns empty | Critical | Stop. The MCP is non-functional. |
| Listed skill folder missing | High | Flag each missing folder. Continue checking others. |
| Malformed JSON-RPC response | High | Report the raw response. Flag as broken. |
| Install command leads with local-only path | High | Flag. Install output must lead with public GitHub route. |
| Docs/catalog language mismatch | Medium | List each mismatch. Flag as hold-with-caveat. |
| Tool implemented but not in catalog | Low | Flag as undocumented. Not a blocker. |
Ship gate rules:
Server:
Commands run:
Tools checked:
Resources checked:
Prompts checked:
Install output:
Failures:
Fixes:
Ship gate: ship | ship-with-caveats | holdAfter QA:
mcp/catalog.json and re-run steps 2 and 7~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.